Tagged: Hashcat
3 posts · browse all tags
-
Password Cracking and Wordlist Engineering Part 2: Hashcat Fundamentals and the GPU Economics of Cracking
Verified against a real hashcat v6.2.6 install and a published RTX 4090 benchmark run: the actual attack-mode syntax, the real mode numbers for NTLM, Kerberoast, and AS-REP, and what it genuinely costs — in dollars, not hand-waving — to exhaust a keyspace against each one.
-
Password Cracking and Wordlist Engineering Part 5: The Rule Engine, best64, and Writing Your Own Mutations
B4ckup$SQL2024 isn't in any wordlist — it's a wordlist entry plus a predictable transform. Walking hashcat's real, bundled best64.rule line by line, what its 102 rules actually do, and writing a custom rule for the one leetspeak substitution best64 doesn't cover.
-
Password Cracking and Wordlist Engineering Part 6: Mask and Hybrid Attacks, and the Keyspace Math Behind Them
No wordlist, no rules — masks build candidates character-position by character-position, and a 40,824-line "compliant password" mask set bundled with hashcat covers realistic complexity-policy shapes 65,000 times more efficiently than blind brute force. The keyspace math for why.